Step Fwd IT Logo

Common SMB1001 Audit Failures (And How to Avoid Them)

Anonymous | September 10, 2026

Many businesses begin preparing for SMB1001 certification expecting the biggest challenge to be technology.

They assume the assessment will uncover missing security tools, outdated systems or major vulnerabilities.

In reality, that's rarely what causes the most difficulty.

Most organisations pursuing SMB1001 already have security controls in place. They have backups running, endpoint protection deployed and multi-factor authentication (MFA) enabled. What often creates challenges during an assessment is something much less obvious.

Documentation.

Accountability.

Evidence.

Governance.

The good news is that the most common SMB1001 audit findings are usually preventable once organisations understand what assessors are actually looking for.

If you're still early in your certification journey, our guide on How to Prepare for SMB1001 Certification provides an overview of the certification process and the key areas businesses should focus on

"Many businesses assume they'll need to implement lots of new technology before an assessment. More often than not, the challenge is demonstrating that existing controls are documented, managed and consistently followed."

Chris Mannering, Director, Step Fwd IT

Most Businesses Don't Fail Because of Technology

One of the biggest misconceptions about SMB1001 certification is that it's primarily a technical assessment.

Technology certainly matters, but SMB1001 is designed to evaluate how cybersecurity is managed across the organisation.

An organisation can have excellent technical controls and still experience difficulties during an assessment if it cannot demonstrate:

  • Who is responsible for cybersecurity
  • How risks are managed
  • How access is controlled
  • How policies are maintained
  • How security activities are reviewed

This distinction is one of the major differences between SMB1001 and the Essential Eight.

As we discussed in our SMB1001 vs Essential Eight article, SMB1001 focuses on broader organisational maturity rather than purely technical security controls.

The question assessors ask is not:

"Do you have security?"

It's:

"Can you demonstrate how security is being managed?"

Common Audit Findings at a Glance

Common FindingWhy It Creates Problems
Missing evidenceSecurity activities can't be verified
Outdated policiesDocumentation no longer reflects reality
Unclear ownershipCritical activities fall through the cracks
Weak user access managementIncreased security and compliance risk
Informal risk managementDecisions can't be clearly demonstrated
Untested backupsRecovery capability is unknown
Treating certification as a projectImprovements become difficult to sustain

The Documentation Gap

If there's one theme that appears consistently during certification preparation, it's documentation.

Many businesses are doing the right things.

They simply haven't documented them.

Policies may exist but haven't been updated in years.

Procedures may be followed consistently but live in the heads of long-serving employees rather than in documented processes.

Risk discussions may occur regularly, but no formal records exist.

From the business's perspective, cybersecurity is functioning.

From an assessor's perspective, there is very little evidence to support that conclusion.

Documentation Assessors Commonly Ask For

Not every assessment is identical, but businesses should expect to produce evidence such as:

  • Cybersecurity policies
  • Risk registers
  • User access reviews
  • Security awareness training records
  • Incident response procedures
  • Backup testing evidence
  • Asset inventories

The strongest organisations aren't necessarily the ones with the most documentation.

They're the ones whose documentation accurately reflects reality.

"We Already Do That" Isn't Evidence

One of the most common conversations during certification preparation sounds something like this:

Assessor: "How often do you review user access?"

Business: "We already do that."

Assessor: "Can you provide evidence of those reviews?"

Business: "Not really."

The same issue appears across many security activities:

  • Staff training is completed, but attendance isn't recorded.
  • Systems are patched, but reports aren't retained.
  • Risk discussions happen, but decisions aren't documented.
  • Backups are running, but restore tests aren't recorded.

The lesson is simple:

Doing the activity is important. Being able to demonstrate it happened is equally important.

In many cases, the gap between a successful certification outcome and an audit finding comes down to evidence.

When Nobody Owns Cybersecurity

As organisations grow, cybersecurity responsibilities often become spread across multiple people.

Management owns some decisions.

Internal staff own others.

An IT provider manages various technical controls.

On paper, everyone is involved.

In reality, ownership can become unclear.

Policy reviews get delayed.

Access approvals happen inconsistently.

Risk reviews don't take place.

Cybersecurity becomes everyone's responsibility.

Which often means it becomes nobody's responsibility.

"One of the biggest indicators of cybersecurity maturity isn't the technology a business uses. It's whether responsibilities are clearly understood and consistently followed."

Chris Mannering, Director, Step Fwd IT

Organisations that perform well during assessments usually have clear accountability structures that define who is responsible for governance, risk management and continual improvement.

Why Risk Management Matters More Than Businesses Expect

Many organisations think about cybersecurity in terms of threats and technology.

SMB1001 encourages organisations to think about risk.

This subtle difference is important.

Risk management helps businesses decide:

  • Which issues should be prioritised
  • Which controls are most important
  • Where resources should be invested
  • How decisions are justified

Without a structured risk management process, cybersecurity decisions often become reactive rather than strategic.

This is why assessors place significant emphasis on risk registers, risk reviews and documented decision-making.

The strongest cybersecurity programs aren't necessarily those that spend the most money.

They're the ones making informed decisions based on risk.

Signs You May Not Be Ready for an SMB1001 Assessment

If several of the following statements apply to your organisation, additional preparation may be worthwhile before beginning certification:

✅ Policies haven't been reviewed in the last 12 months

✅ Cybersecurity responsibilities are not clearly assigned

✅ Security activities are being performed but not documented

✅ User access reviews happen informally

✅ Risks are discussed but not formally recorded

✅ Backup restores have not been tested recently

✅ Security awareness training is not tracked

✅ Documentation doesn't accurately reflect current business practices

A single tick doesn't mean certification is out of reach.

However, multiple gaps often indicate areas that would benefit from attention before an assessment.

The Certification Trap

Perhaps the most significant mistake organisations make is treating SMB1001 certification as a one-time project.

A project has a finish line.

A maturity framework doesn't.

Businesses sometimes invest significant effort preparing for an assessment, only to discover that maintaining compliance requires an ongoing commitment.

The organisations that achieve the strongest outcomes take a different approach.

They view SMB1001 as a framework for continual improvement rather than a compliance exercise.

"The organisations that perform best during assessments are usually the ones that view certification as part of an ongoing improvement journey rather than a box-ticking exercise."

Chris Mannering, Director, Step Fwd IT

A Quick SMB1001 Readiness Check

QuestionIf the Answer is "No"...
Can we clearly identify who owns cybersecurity governance?Accountability may be unclear
Are cybersecurity policies reviewed regularly?Documentation may need attention
Can we produce evidence of key security activities?Evidence collection may be inconsistent
Are cybersecurity risks formally documented?Risk management may be immature
Have backups been tested recently?Recovery capability may be uncertain
Are user access reviews documented?Access management controls may require improvement

This isn't a formal assessment.

However, it provides a useful indication of where common gaps may exist.

What Assessors Are Really Looking For

One of the most reassuring things businesses discover about SMB1001 is that assessors are not looking for perfection.

What they want to see is evidence that cybersecurity is being approached in a structured and deliberate way.

At a high level, assessors are generally looking for:

  • Defined responsibilities
  • Documented processes
  • Consistent security practices
  • Evidence that controls are operating
  • Ongoing improvement activities

Assessors are generally looking for consistency, reasoned decision-making and documented processes that reduce risk rather than perfection.

That's an important distinction.

Most organisations already have pieces of the puzzle in place.

The challenge is bringing them together into a framework that can be managed, reviewed and demonstrated consistently.

Frequently Asked Questions

What is the most common SMB1001 audit failure?

A lack of evidence is one of the most common issues. Many organisations perform security activities but cannot easily demonstrate that those activities have occurred.

Will one audit finding cause certification to fail?

Not necessarily. Assessments evaluate overall maturity rather than focusing on a single control in isolation.

How can I prepare for an SMB1001 assessment?

A good starting point is to review your documentation, validate technical controls and ensure evidence is available. Our guide on How to Prepare for SMB1001 Certification explores this in more detail.

Does SMB1001 only focus on technology?

No. SMB1001 evaluates governance, risk management, documentation, accountability and technical controls.

Is SMB1001 similar to the Essential Eight?

There is some overlap, particularly around cybersecurity controls. However, SMB1001 provides a broader framework for organisational maturity and certification.

The Bottom Line

Most SMB1001 audit findings are not caused by a lack of technology.

They're caused by a lack of documentation, evidence, accountability or structure.

The businesses that perform best during certification aren't necessarily the ones with the largest IT budgets or the most sophisticated security tools.

They're the organisations that can clearly demonstrate how cybersecurity is being managed, reviewed and improved over time.

"Certification shouldn't be viewed as a test to pass. It should be viewed as an opportunity to strengthen the way your organisation manages cybersecurity."

Chris Mannering, Director, Step Fwd IT

Preparing for an SMB1001 Assessment?

Whether you're exploring certification for the first time or actively preparing for an upcoming assessment, understanding your current level of cybersecurity maturity is often the best place to start.

Step Fwd IT can help identify potential gaps, review existing controls and build a practical roadmap towards certification.

If you're unsure where your organisation currently stands, a readiness assessment can provide clarity before the formal certification process begins.

Related Insights

chevron-downchevron-leftchevron-right